cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
567
Views
1
Helpful
4
Replies

Is it possible to disable the Non SSL Anyconnect Login

Scott Dunseth
Level 1
Level 1

I am doing a vulnerability scan of our NGFW 1120 and I am able to see the unsecure site that shows the IP and VPN login - is there a way that we can disable the access to the unsecure side and only allow the SSL connection to be visible?

Thank you

1 Accepted Solution

Accepted Solutions

"Not secure", when shown in a browser toolbar like you shared, usually means the certificate common name (or subject alternate name) does not match the FQDN you scanned. For instance, scanning using the IP address instead of the FQDN will usually show such output.

For a better scanning option, I typically use ssllabs.com server test here: https://www.ssllabs.com/ssltest/

View solution in original post

4 Replies 4

can you more elaborate?

Scott Dunseth
Level 1
Level 1

I am scanning the external IP of our Firewall NGFW 1120 - the scan is picking up the IP Address of the vpn, and the secure site of the vpn is good (as expected).  Here is the example (below)  Is it possible to block the access to this - so that the Secure VPN site is the only accessible site shown. (Screenshot at the bottom)

ScottDunseth_0-1686157396246.png

 

 

Secure Site

ScottDunseth_1-1686157540973.png

Thank you

"Not secure", when shown in a browser toolbar like you shared, usually means the certificate common name (or subject alternate name) does not match the FQDN you scanned. For instance, scanning using the IP address instead of the FQDN will usually show such output.

For a better scanning option, I typically use ssllabs.com server test here: https://www.ssllabs.com/ssltest/

I would like to make sure the Firewall does not show the unsecure site.  I would like the Secure Site with the Cert to be the only one available.

Thank you